{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-04","description":"Continuously monitor third-party performance, service delivery, and security posture against contractual and risk requirements throughout the relationship. Conduct periodic reassessments and reviews, such as questionnaires, assurance reports, and audits, at a frequency based on criticality, and manage changes to supplier services. Record, prioritize, and track identified vendor risks through response and remediation.","details":{"control_category":"administrative","control_type":"detective","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"SR-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.SC-07","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.SC-09","coverage":"partial","delta":"integration of practices across the technology life cycle satisfied by program control","framework":"nist-csf-2","relationship":"intersects_with"},{"control_id":"A.5.22","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Continuously monitor third-party performance, service delivery, and security posture against contractual and risk requirements throughout the relationship. Conduct periodic reassessments and reviews, such as questionnaires, assurance reports, and audits, at a frequency based on criticality, and manage changes to supplier services. Record, prioritize, and track identified vendor risks through response and remediation.","title":"Monitor vendor performance, services, and risk","unified_id":"UC-TPRM-04"},"id":"uc:UC-TPRM-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-04","sourceIds":["iso-27001","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-TPRM-04 — Monitor vendor performance, services, and risk","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:22bc47e9fae7602db86a40b080e510b4102677711a06b10343505318193f517e","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e3ae93648bf8b35bfcb513a4b4f60cf1b825e2af925b9834ada14d699c57067","properties":{"rationale":"Questionnaires, assurance-report review, and audits surface vendor compliance drift, reducing vicarious-liability exposure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","sourceId":"uc:UC-TPRM-04","targetDetailPath":"/data/v1/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.json","targetId":"risk:tprm-vendor-compliance-vicarious-liability","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4213ed0177e7208cbd35e7e309550a359595b2a95e5998d6bb3dc452402bff28","properties":{},"sourceDetailPath":"/data/v1/records/wf-d56-387bb72b.json","sourceId":"wf:D56","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5c67a9d5447c15818d31c136aeaa8113f0dba779388f9bd63ba07dce1528e891","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:656ac62569a0bb48ad16dfeedf7baf6154882714af6ad0539f9a6cdb2613fc40","properties":{},"sourceDetailPath":"/data/v1/records/wf-d55-248b03a5.json","sourceId":"wf:D55","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:709fcc459cd44ee480f15e5b5638d9bb67a1baed9f95ad747e1d2a3906313eb0","properties":{"control_id":"GV.SC-07","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","sourceId":"uc:UC-TPRM-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-07-640ab80f.json","targetId":"ctrl:nist-csf-2:GV.SC-07","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8057572cda7b21587d3ec5893138ab77675283df290c0008f883c11becee8803","properties":{},"sourceDetailPath":"/data/v1/records/wf-c11-f590792c.json","sourceId":"wf:C11","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:83fa61e39da7dc642db6d6a45bef999d83b0ffdcd735a0ff3151ef30bf0d9ee0","properties":{"control_id":"SR-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","sourceId":"uc:UC-TPRM-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-6-b55551c2.json","targetId":"ctrl:nist-800-53:SR-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b5339b55f3cfa07fa148380586286f6166a50636b410e705ccac8c513dd8971","properties":{"rationale":"Periodic reassessment and posture monitoring surface a deteriorating critical vendor early, reducing failure impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","sourceId":"uc:UC-TPRM-04","targetDetailPath":"/data/v1/records/risk-tprm-critical-vendor-failure-cb39c2bc.json","targetId":"risk:tprm-critical-vendor-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a49a486d083153ad59e40694fb7939ea084461d9da86e629e8a95c447f699dcb","properties":{},"sourceDetailPath":"/data/v1/records/wf-a7-454c1d0e.json","sourceId":"wf:A7","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a551bddc490cc9670d58a68a71bbf0d51f6700dc3781112c63d898ba19313b3c","properties":{"control_id":"GV.SC-09","coverage":"partial","delta":"integration of practices across the technology life cycle satisfied by program control","framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","sourceId":"uc:UC-TPRM-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-09-4150236a.json","targetId":"ctrl:nist-csf-2:GV.SC-09","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ad4b2fe0e6f7c737b286d4544d3cdd3d897a1f071bbc3a8cbfa5cafcc7e0ba6c","properties":{},"sourceDetailPath":"/data/v1/records/wf-g29-6f0c8a46.json","sourceId":"wf:G29","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be7be015b760fa1f75849f34d7565aeaa8520546de834ef74aa7b0c24e119b58","properties":{},"sourceDetailPath":"/data/v1/records/wf-d54-eba5e14e.json","sourceId":"wf:D54","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d26581abe3d46f172ea9ca142974efef5f7f7b32914c71a5944100c0680ea487","properties":{},"sourceDetailPath":"/data/v1/records/wf-r6-824a647c.json","sourceId":"wf:R6","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e466aaaf6f8859006cd1146f7d023488f9ebc3c9a159d86492ffa0664add6948","properties":{},"sourceDetailPath":"/data/v1/records/wf-d32-3114234e.json","sourceId":"wf:D32","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f92fde77cb6575136885ea6c52248547e35fb71e3474c0eeb0ef6784819161b4","properties":{"rationale":"Continuously monitoring third-party service delivery and security posture with periodic reassessment is precisely the monitoring the risk says is absent.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","sourceId":"uc:UC-TPRM-04","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fa7bb83970f87aca8d124a6705ff493a0e6d3eb5cfaf2968168727d982037956","properties":{"rationale":"Monitoring performance and service delivery against contractual and SLA requirements directly detects and drives remediation of non-performance.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","sourceId":"uc:UC-TPRM-04","targetDetailPath":"/data/v1/records/risk-tprm-vendor-service-nonperformance-081f2fb9.json","targetId":"risk:tprm-vendor-service-nonperformance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:faaa84666a0a8ed0d3fcc11ce04b8b4ec70c8e96aae124692bdf43e95c3b7273","properties":{"control_id":"A.5.22","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","sourceId":"uc:UC-TPRM-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-22-bb292d09.json","targetId":"ctrl:iso-27001:A.5.22","type":"maps_to"}],"schemaVersion":1}
